Bug 2228459 - AIDE compliancy [rhel-8.6.0.z]
Summary: AIDE compliancy [rhel-8.6.0.z]
Keywords:
Status: VERIFIED
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: scap-security-guide
Version: 8.7
Hardware: All
OS: Linux
medium
medium
Target Milestone: rc
: ---
Assignee: Jan Černý
QA Contact: Milan Lysonek
URL:
Whiteboard:
Depends On: 2175684
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-08-02 12:18 UTC by RHEL Program Management Team
Modified: 2023-08-17 15:25 UTC (History)
6 users (show)

Fixed In Version: scap-security-guide-0.1.69-1.el8_6
Doc Type: Bug Fix
Doc Text:
Fixed rules related to AIDE configuration Rule `aide_build_database` no longer requires the existence of the `/var/lib/aide/aide.db.new.gz` file which contains the freshly generated AIDE database. The reason is that this database isn't needed for AIDE to work, only the installed database at `/var/lib/aide/aide.db.gz` is needed by AIDE. Users can install the freshly generated database by moving the file from `/var/lib/aide/aide.db.new.gz` to `/var/lib/aide/aide.db.gz`. Previously, the rule required the existence of both `/var/lib/aide/aide.db.new.gz` and `/var/lib/aide/aide.db.gz` in order to pass. Now, it requires only the existence of `/var/lib/aide/aide.db.gz` in order to pass. Rule `aide_periodic_cron_checking` has been changed to be less strict on entries in `/etc/cron.daily` and `/etc/cron.weekly`. That allows administrators to schedule the `aide --check` command with additional wrappers while staying compliant with the rule.
Clone Of: 2175684
Environment:
Last Closed:
Type: ---
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-164136 0 None None None 2023-08-02 12:21:53 UTC


Note You need to log in before you can comment on or make changes to this bug.